OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.
The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.
Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities.
OnTrac is a private American parcel-delivery company specializing in “last-mile” e-commerce deliveries, formed in 2021 from the merger of OnTrac Logistics and LaserShip.
The firm operates at 102 locations across 35 states, covering roughly 70% of the U.S. population, and working with more than 7,000 independent delivery contractors.
In response to the security incident, OnTrac contracted a third-party specialist to help determine the scope of the breach and took steps to “ensure the data described above was re-secured and not distributed.”
This statement suggests a possible agreement between the firm and the attackers, typically a ransom payment, to make sure that the customer information is not leaked.
“We are not aware of any fraud or publication of stolen information resulting from this incident, nor do we have any reason to believe any such misuse of information will occur,” OnTrac says in the notification.
To help exposed customers mitigate the risks that may arise from the exposure of their sensitive data, OnTrac is offering free-of-charge access to a 12-month credit monitoring and identity protection service via CyberScout, with a 90-day enrollment deadline.
Recipients of the letter are also recommended to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if the risk is deemed significant.
BleepingComputer has contacted OnTrac to learn more about the attack, the number of impacted clients, and whether a ransom was paid, but we have not heard back by publication time.
At the time of writing, no ransomware or data extortion threat groups have taken responsibility for the attack.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Ernst & Young discloses data breach after support system hack
Healthtech firm Xolis suffers data breach impacting 1.4 million people
Upbound says hack caused $13 million in fraudulent Acima leases
Medtronic notifies customers impacted by ShinyHunters data breach
LastPass confirms data breach in Klue supply chain attack
OpenAI confirms ChatGPT is down worldwide
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Microsoft blames massive Microsoft 365 outage on maintenance bug
Your Scanners Are Green. Your Pipeline Might Not Be. Here’s How to Close the Gap.
Calculate what you’d save by replacing your MDR.
AI agents can speed up ransomware attacks. See how Acronis helps reduce the risk.
Overdue a password health-check? Audit your Active Directory for free
Rev5 is ending. See what your FedRAMP 20x transition really requires
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



